Conversation
preview now carries the same tree as main and dev (36aed0b). The version string is the only difference, which is what the release workflow requires: preview publishes prerelease versions under the 'preview' dist-tag. Before this, the preview channel was 12,065 lines behind dev and still shipped the Compatibility Lab on every install's request path.
chore(preview): promote dev for the v2.20.0 line
[WRONG BRANCH] Merge dev into preview: Windows suite green
Merge dev into preview: ignore leftover test temp files
Merge main into preview: v2.24.2 release
Promote dev to preview: Wave 5 campaign (107 commits)
Promote dev to preview: CodeQL #87 ReDoS fix + closeout correction
Promote dev to preview: Wave 5 record corrections
Promote dev to preview: alert-precision record
Promote dev to preview: post-scan closing note
Promote dev to preview: final Wave 5 errata
Promote dev to preview: Wave 5 closing record
Promote dev to preview: v2.25.0 release train
release: v2.25.0-preview.20260818
promote: dev to preview for v2.26.0-preview.20260819
release: v2.26.0-preview.20260819
fix(gui): show the device code and authorization link on every login surface
fix(gui): render the login hint during a first-time provider add
feat(oauth): let the operator decline a proxy-side browser open
fix(oauth): read code and state from a redirect URL fragment
fix(oauth): never pair a code and state from different URL components
merge dev into preview for the v2.33.0-preview.20260825 release
…parity fix(release): run the preflight suite in the same groups CI does
merge dev into preview for the v2.33.0-preview.20260825 release (release-gate parity)
…on-oracle test(usage): stop asserting the overlay version against a moving oracle
|
Caution Review failedThe pull request is closed. ℹ️ Recent review info⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: ASSERTIVE Plan: Pro Plus Run ID: 📒 Files selected for processing (131)
📝 WalkthroughWalkthroughThis change combines OAuth login UX improvements, configurable model compaction limits, operator diagnostics, tool handling updates, retry behavior, documentation, and test infrastructure changes. ChangesOAuth login experience
Model catalog compaction budgets
Operator visibility and runtime behavior
Estimated code review effort: 5 (Critical) | ~120 minutes Sequence Diagram(s)sequenceDiagram
participant GUI
participant OAuthRoute
participant OAuthProvider
participant CallbackParser
GUI->>OAuthRoute: start login with openBrowser preference
OAuthRoute->>OAuthProvider: create login flow
OAuthProvider-->>OAuthRoute: URL, device code, instructions
OAuthRoute-->>GUI: login metadata
GUI->>CallbackParser: submit pasted URL or code
CallbackParser-->>OAuthRoute: validated code and state
OAuthRoute-->>GUI: login result
✨ Finishing Touches 💡 2⚔️ Resolve merge conflicts 💡
🛠️ Fix failing CI checks 💡
📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
✅ Deterministic PR hygiene checks passed. |
⏳ DRAFT
What to do
Its title has been prefixed with |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: e1fb675595
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| || normalized.includes("/mise/shims/") | ||
| || normalized.includes("/.asdf/installs/") | ||
| || normalized.includes("/.asdf/shims/") | ||
| || normalized.includes("/.volta/"); |
There was a problem hiding this comment.
Recognize Volta's default Windows installation path
On Windows, Volta normally installs under %LOCALAPPDATA%\Volta\bin, which normalizes to a path containing /volta/, not /.volta/. Consequently this classifier returns false for the standard Windows Volta layout, so after a Volta upgrade autoRestoreCodexShim can adopt and wrap the replacement binary again; the next upgrade destroys that shim and can silently leave Codex routing native. Match the Windows Volta layout as well and cover it with the actual default path rather than C:\Users\u\.volta\....
Useful? React with 👍 / 👎.
| export function OpenBrowserPrefToggle({ serverDefault = true }: { serverDefault?: boolean }) { | ||
| const t = useT(); | ||
| const [choice, setChoice] = useState<boolean | undefined>(readOpenBrowserPref); | ||
| const open = choice ?? serverDefault; |
There was a problem hiding this comment.
Render the persisted browser-open setting in the toggle
When oauthOpenBrowser is persisted as false and this browser has no localStorage preference, both current call sites omit serverDefault, so this default makes the “Don't open a browser” checkbox appear unchecked even though login requests omit openBrowser and the server therefore does not open one. The control visibly contradicts the effective configuration; pass the fetched setting into the component or represent the inherited server state explicitly.
AGENTS.md reference: gui/AGENTS.md:L10-L10
Useful? React with 👍 / 👎.
| for (const line of unusedProxyWarningLines({ | ||
| proxyUp: Boolean(status.json.proxy.pid || status.json.proxy.health.ok), | ||
| routingKind: status.json.startup.routingKind, |
There was a problem hiding this comment.
Exclude stale PID files from the unused-proxy warning
When a stale PID file exists but the health check fails, collectStatus deliberately reports proxy.running: false and labels the PID as stale, yet this new predicate treats the mere non-null PID as an active proxy and prints “the running proxy is unused.” That makes the new routing diagnostic contradict the status immediately above it; derive proxyUp from proxy.running or a successful health check instead of PID-file presence.
Useful? React with 👍 / 👎.
Promotion of dev into main for the 2.33.0 stable release.
Contents: the four OAuth login UX PRs (#2530, #2534, #2537, #2540), the mixed query/fragment authorization-response fix (#2543) found by an independent release-readiness audit, the release-gate isolation parity fix (#2546), and the api-usage overlay-version oracle fix (#2549).
The same code is already published as 2.33.0-preview.20260825 from preview, with the tarball verified by content.
Summary by CodeRabbit
New Features
Bug Fixes
Documentation